01 / Lead assessment

Know where your Microsoft 365 stands—and what to do next.

A focused look at key security controls and the IT support behind them. You get findings you can understand, questions to put to your provider, and a plan for the next 90 days.

For: growing businesses using Microsoft 365Format: defined scope, findings and readout
What we examine

A useful picture of risk, not just a score.

The exact checks depend on your licences, environment and goals. We agree the scope before accessing anything, then review the controls and service information that matter to your decision.

  • Multifactor authentication and sign-in policies
  • Privileged roles and dormant accounts
  • Device management and protection coverage
  • Email protection and domain authentication
  • Third-party application access
  • Support responsibilities and current IT costs
How access works: We agree permissions with you and use read-only access where practical. A security review examines the agreed evidence; it is not a penetration test or a guarantee that every risk has been found.
Your deliverables

A report designed to lead to action.

01 / FINDINGS

Evidence and context

What we observed, why it matters and where the evidence came from.

02 / PRIORITIES

90-day action plan

Recommended actions sequenced by urgency and practical impact.

03 / DISCUSSION

Findings readout

A conversation to clarify trade-offs, ownership and your next decision.

Illustrative report extract

See how a finding becomes a decision.

This fictional example shows the format of a recommendation. Actual findings depend on the agreed review scope and evidence.

EXAMPLE / 01Priority: High

Review privileged sign-in exceptions

Evidence
One example administrator account is excluded from the policy requiring multifactor authentication. Its purpose and compensating controls are not documented in this example.
Why it matters
An unmanaged exception could allow a privileged sign-in without the expected control. A legitimate emergency account needs a documented design and monitoring.
Recommended action
Confirm who owns the exception, verify the account's purpose, review sign-in logs, and agree the appropriate policy or emergency access controls.
Suggested owner: IT lead / MSPTarget: first 30 days
A sensible starting point

Bring your current provider into the solution.

Most findings can be assigned to an existing IT team or MSP. We make the requested change and its reason clear, so you can track progress without needing to become the technical middleman.

If you need implementation support or longer-term oversight, we will scope it separately and explain any commercial relationships before you decide.

Explore the MSP review

Your MSP provides patching—but can it prove every device is current?

Read the patching guide
Start with a conversation

What would you like to understand about your environment?

Tell us your concern and we will propose a review scope that fits the decision you need to make.

Request a review